AnsweredAssumed Answered

Can we create nested rule in RSA Netwitness Packets and logs?

Question asked by Avdoot Kumbhar on Jan 10, 2018
Latest reply on Jan 11, 2018 by Christopher Ahearn

I want to create rule which will take output from one rule and use it in a new rule.

***********************************************************

Rule 1-

 

Select

 

event.time, ip.src, country.src, ip.dst, ip.dstport, action, event.desc

 

Where

 

event.desc contains "scanner" && device.class != 'Anti Virus' 

 

Rule 2- 

 

Select

 

event.time, ip.src, country.src, ip.dst, ip.dstport, action, event.desc

 

Where

 

ip.src = (Source IP address from Rule 1 output)

 

*********************************************************

Hope that is clear.

Outcomes